AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection
Brief
AI-powered malware is making a familiar security problem harder to contain. Instead of keeping the same code long enough for antivirus tools to recognize it, these programs can alter their form repeatedly while retaining the same harmful purpose.
The emerging model relies on large language models as an automated code factory. A malicious dropper can request a newly obscured version of itself at regular intervals, while related tools can generate short commands for collecting documents.
That reduces the time and specialist skill traditionally needed to create fresh samples. Morphisec analysts noted the shift after reviewing reports of PROMPTFLUX, an experimental dropper disclosed by Google’s threat researchers in late 2025.
The sample reportedly queried the Gemini API about once an hour and regenerated obfuscated code, with researchers seeing more than 70 variants in under four hours.
